server.py prints exactly one line per login attempt — whatever request
body actually arrives. What's in that body is entirely up to which mode the client uses.
Pick a login, flip the mode, and read the server's own log for yourself — real SHA-256 and real
HMAC-SHA256, the same primitives common.py uses, computed live in your browser.
Mode — which docker-compose file would be running:
What the client actually sends, and the server's own log line for it:
What was computed (real SHA-256 + real HMAC-SHA256 — common.py's
exact construction, nothing scripted):
server.py's own print() outputA compromised server, an over-eager third-party logging SaaS, or anyone who later breaches the log store — not a network eavesdropper. TLS never touches this.
The same log reader, trying to log in again using only what they just captured — no new access, nothing extra.